CVE-2009-3733
Summary
| CVE | CVE-2009-3733 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-02 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Application | Vmware | Esx | 3.0.3 | All | All | All |
| Application | Vmware | Esx | 3.5 | All | All | All |
| Application | Vmware | Esxi | 3.5 | All | All | All |
| Application | Vmware | Server | 1.0 | All | All | All |
| Application | Vmware | Server | 1.0.1 | All | All | All |
| Application | Vmware | Server | 1.0.1_build_29996 | All | All | All |
| Application | Vmware | Server | 1.0.2 | All | All | All |
| Application | Vmware | Server | 1.0.3 | All | All | All |
| Application | Vmware | Server | 1.0.4 | All | All | All |
| Application | Vmware | Server | 1.0.4_build_56528 | All | All | All |
| Application | Vmware | Server | 1.0.5 | All | All | All |
| Application | Vmware | Server | 1.0.6 | All | All | All |
| Application | Vmware | Server | 1.0.7 | All | All | All |
| Application | Vmware | Server | 1.0.8 | All | All | All |
| Application | Vmware | Server | 1.0.9 | All | All | All |
| Application | Vmware | Server | 2.0.0 | All | All | All |
| Application | Vmware | Server | 2.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Products Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| SecurityTracker.com Archives - VMware Server Directory Traversal Flaw Lets Remote Users Obtain Arbitrary Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| [Security-announce] VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| VMware Products Directory Traversal File Disclosure Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - VMware ESX/ESXi Directory Traversal Flaw Lets Remote Users Obtain Arbitrary Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| VMSA-2009-0015 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.